CVE-2025-54906

7.8

Microsoft · Office

A use-after-free vulnerability in Microsoft Office allows an unauthorized attacker to achieve local code execution.

Executive summary

A critical memory corruption vulnerability in Microsoft Office products permits unauthorized local code execution, posing a significant risk to system integrity.

Vulnerability

This is a use-after-free vulnerability (CWE-416) occurring when memory is incorrectly freed outside of the heap, potentially allowing an unauthorized local attacker to execute arbitrary code.

Business impact

Successful exploitation of this vulnerability could lead to a total compromise of the host system, including data theft, privilege escalation, or installation of persistent malware. With a CVSS score of 7.8, this flaw represents a High severity threat, specifically because it enables code execution that can bypass standard application-level controls.

Remediation

Immediate Action: Apply the latest security updates provided by Microsoft via the official update guide at https://aka.ms/OfficeSecurityReleases immediately.

Proactive Monitoring: Monitor endpoint security logs for unusual process spawning or unexpected crashes associated with Office applications.

Compensating Controls: Ensure that users operate with the least privilege necessary, and utilize endpoint detection and response (EDR) tools to identify suspicious memory-related activity.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for code execution, organizations should prioritize the deployment of the identified security patches across all affected Microsoft Office installations. Failure to update may leave endpoints vulnerable to local exploitation, leading to full system compromise. Patching remains the only definitive method to remediate this use-after-free vulnerability.

More Microsoft CVEs

Sources